Prepare Cloudflare Production Deployment
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
A skill your agent uses when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and…
$ npx skills add ericrisco/rsc-harness --skill domains-dns -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness domains-dns --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/domains-dns .claude/skills/domains-dns && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "domains-dns" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/domains-dns into .claude/skills/domains-dns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domains-dns", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/domains-dnsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill domains-dns -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness domains-dns --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/domains-dns .agents/skills/domains-dns && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "domains-dns" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/domains-dns into .agents/skills/domains-dns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domains-dns", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill domains-dns -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness domains-dns --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/domains-dns .cursor/skills/domains-dns && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "domains-dns" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/domains-dns into .cursor/skills/domains-dns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domains-dns", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/domains-dns--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill domains-dns -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness domains-dns --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/domains-dns .gemini/skills/domains-dns && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "domains-dns" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/domains-dns into .gemini/skills/domains-dns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domains-dns", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness domains-dnsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill domains-dns -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/domains-dns .github/skills/domains-dns && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "domains-dns" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/domains-dns into .github/skills/domains-dns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domains-dns", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill domains-dns -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness domains-dns --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/domains-dns .opencode/skills/domains-dns && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "domains-dns" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/domains-dns into .opencode/skills/domains-dns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domains-dns", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
domains-dnsA skill your agent uses when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and…
Domains DNS is an agent skill from ericrisco/rsc-harness. Use when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and cutting nameservers over without downtime. NOT inbox placement or warmup (that is email-deliverability), NOT what runs behind the name (that is deployment).
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/record-cookbook.md`).
It sits in DevOps & Cloud, covering Cloud networking, Transactional email and Email management. It works with Cloudflare. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
opensslcurlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Domains DNS loads about 2.4k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 1,150 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,150 words, ~2,439 tokens.
.claude/skills/domains-dns/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.You set up a name end to end: register or delegate it, write the records, and serve valid HTTPS. Almost every "my domain doesn't work" report is one of a handful of recurring mistakes. This skill names them and gives you paste-ready records plus the commands to prove they took.
A request resolves in one direction. Diagnose in the same direction, top-down, because the bug is almost always at the layer the user is not looking at.
whois)dig NS)dig @<authoritative-ns>)openssl s_client)Rule: never debug TLS before you've confirmed the record resolves to the box you think it does — a cert error is often a record pointing at the wrong host. Query authoritative nameservers, not your laptop's cache, or you'll chase a stale answer for an hour.
Pick one authoritative provider and keep the whole zone there. Splitting a zone across two providers (some records at the registrar, some at Cloudflare) is the source of "it works for me but not for them" — resolvers see whichever NS set answered.
| Host the zone at | Choose when | Why |
|---|---|---|
| Registrar DNS (GoDaddy, Namecheap, Porkbull) | Tiny static site, one or two records | One vendor, fewer logins; weak APIs and slow propagation |
| Dedicated DNS (Cloudflare, DNSimple) | Most cases; want CNAME flattening + fast edits | Apex flattening, low TTL edits, good API; see ../cloudflare/SKILL.md |
| Cloud DNS (Route 53, Cloud DNS) | Already all-in on AWS/GCP and want alias-to-LB | Native alias records to cloud load balancers |
| Host-managed (Vercel, Netlify) | The host is the only thing the domain serves | Auto-TLS + apex flattening handled for you; see ../vercel/SKILL.md |
You cannot put a CNAME at the zone apex (the naked example.com). The spec forbids a CNAME coexisting with the SOA and NS records that must live there (RFC 1034 §3.6.2, RFC 2181). Registrars that let you save it produce a silently broken zone.
# Bad — CNAME at the apex. Breaks SOA/NS; mail and other apex records vanish.
example.com. CNAME cname.vercel-dns.com.
# Good — flatten at the apex (ALIAS/ANAME or provider flattening), CNAME only on the subdomain.
example.com. ALIAS cname.vercel-dns.com. # Cloudflare/Netlify/Route53/DNSimple equivalent
www.example.com. CNAME cname.vercel-dns.com.
# Good (no flattening available) — hard-code the host's published A/AAAA at the apex.
example.com. A 76.76.21.21
www.example.com. CNAME cname.vercel-dns.com.Then pick one canonical host and 301 the other to it (apex→www or www→apex — either, just be consistent). Two live origins split your SEO and your cookies. The redirect lives at the host/edge, not in DNS.
One example row per type. Edge cases — TXT 255-char chunking, MX priority math, the SPF 10-lookup limit, SRV format, NS/SOA, PTR, DNSSEC — live in references/record-cookbook.md.
| Type | Use for | Example (name → value) |
|---|---|---|
A | name → IPv4 | app → 76.76.21.21 |
AAAA | name → IPv6 | app → 2606:4700::6810 |
CNAME | subdomain → another name (never apex) | www → cname.vercel-dns.com. |
ALIAS/ANAME | apex → another name (flattened to A/AAAA) | @ → cname.netlify.app. |
MX | where mail is delivered (priority, lower = first) | @ → 10 mail.example.com. |
TXT | SPF / DKIM / DMARC / domain-verification | @ → "v=spf1 include:_spf.google.com ~all" |
CAA | which CA may issue certs | @ → 0 issue "letsencrypt.org" |
SRV | service discovery (proto/port) | _sip._tcp → 10 5 5060 sip.example.com. |
The SPF/DKIM/DMARC/MX rows belong here. Whether mail lands — reputation, warmup, inbox placement — is ../email-deliverability/SKILL.md.
The 2026 reality: the CA/Browser Forum cut the maximum public-TLS lifetime to 200 days (from 398) on 2026-03-15, dropping to 100 days on 2027-03-15 and 47 days on 2029-03-15; domain-validation reuse is capped the same way (200 → 100 → 10 days). Manual annual certs are dead. Automate renewal or accept guaranteed outages.
Decision: how does the CA prove you control the domain?
| Challenge | Use when | Cost |
|---|---|---|
| HTTP-01 | Single host, port 80 reachable, no wildcard | Simplest; needs inbound :80 |
| DNS-01 | Wildcard cert, or port 80 closed, or cert issued off-box | Needs API access to write a _acme-challenge TXT |
Rules, each with the failure it prevents:
0 issue "letsencrypt.org". Wildcards need the separate issuewild tag. A CAA that omits your CA makes ACME fail with a CAA error before any cert is issued (RFC 8659).curl and mobile — the classic "works on my machine" TLS bug. Serve fullchain.pem.certbot/acme.sh recipes, wildcard via DNS-01, Cloudflare Full vs Full(strict), and the renewal-automation + ARI detail are in references/tls-and-acme.md.
Query the authoritative answer and the wire, never your local cache.
dig +short app.example.com # the resolved record, your resolver's view
dig +trace example.com # full delegation chain from the root — spot stale NS
dig @ns1.provider.net example.com A # ask the authoritative NS directly
dig CAA example.com +short # confirm the CA you use is allowed
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null \
| openssl x509 -noout -subject -issuer -dates # served chain subject/issuer + validity window
curl -vI https://example.com 2>&1 | grep -Ei 'HTTP/|location|SSL certificate' # status + redirect + cert verdictPropagation is governed by TTL, not a fixed 48 hours (RFC 2181). To make a change land fast, lower the record's TTL (e.g. to 300s) before you change it, so resolvers re-query sooner. NS/registrar delegation changes can still lag because of registry/TLD TTLs.
scripts/verify.sh <domain> runs the whole done-check read-only: apex-CNAME check, CAA sanity, chain completeness + expiry, HTTPS reachability, www↔apex canonical. The full dig/openssl/curl playbook and an error → cause → fix table are in references/verify-and-debug.md.
Order matters; each step has a reason.
dig +trace and dig @<new-ns> until the new NS answer is global. Don't trust your browser.| Anti-pattern | Why it bites | Do instead |
|---|---|---|
| CNAME at the apex | Illegal per spec; kills SOA/NS, MX, and other apex records | ALIAS/flattening or hard A/AAAA at apex |
| "Wait 48 hours" for propagation | Propagation is the TTL; you're just guessing | Lower TTL before change; verify with dig +trace |
| Confirming a change in your browser | Local/OS resolver cache lies for the old TTL | Query authoritative NS or @1.1.1.1 |
| Manual yearly cert renewal | Max lifetime is 200d now, 47d by 2029 — it will expire | ACME auto-renew or platform-managed TLS |
| Issuing certs with no CAA / wrong CAA | ACME fails with a CAA error before issuance | CAA 0 issue "<your-ca>"; add issuewild for wildcards |
| Serving the leaf cert only | Browsers cache intermediates; curl/mobile break | Serve fullchain.pem |
| Splitting one zone across two providers | Resolvers answer from whichever NS won; records vanish intermittently | One authoritative provider per zone |
| TTL left at 86400 during migration | Old answer cached for a day after you flip | Drop to 300s a day ahead |
| Testing certs against ACME production | Burns the 50-cert/7-day limit; week-long lockout | Use the staging endpoint first |
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in skills/domains-dns of ericrisco/rsc-harness.
Open the folder on GitHubat commit e3d5b33
Domains DNS next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Domains DNS this skillericrisco/rsc-harness | 174 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template | 786 | — | ~5.9k | Automated safety check: Notes | MIT | |
| OmniRoute Tunnel CLIdiegosouzapw/OmniRoute | 74k | — | ~339 | Automated safety check: Pass | MIT | |
| OmniRoute Tunnelsdiegosouzapw/OmniRoute | 74k | — | ~209 | Automated safety check: Pass | MIT | |
| Cdn Setupsickn33/agentic-awesome-skills | 47k | 2 repos | ~2.9k | Automated safety check: Pass | MIT | |
| DNS Managementsickn33/agentic-awesome-skills | 47k | 2 repos | ~2.7k | Automated safety check: Pass | MIT |
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
diegosouzapw/OmniRoute
Starts, stops, and inspects ngrok, Cloudflare, or custom tunnel connections from the command line, including auth and reachability.
diegosouzapw/OmniRoute
Create and manage secure tunnels (ngrok, Cloudflare Tunnel, custom) to expose OmniRoute to the internet or share access with remote agents and CI pipelines.
sickn33/agentic-awesome-skills
Configure CDNs for content delivery. An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Configure DNS zones and records. An agent skill from sickn33/agentic-awesome-skills.
ancoleman/ai-design-components
Manage DNS records, TTL strategies, and DNS-as-code automation for infrastructure.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Works with
Categories
A skill your agent uses when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and…. Domains DNS is an agent skill from ericrisco/rsc-harness. Use when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and cutting nameservers over without downtime.
Domains DNS fits situations like: pointing a domain at a host; fixing broken HTTPS — delegating nameservers; writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows; standing up auto-renewing TLS.
Run `npx skills add ericrisco/rsc-harness --skill domains-dns -a claude-code`. Or copy the skill folder (skills/domains-dns in ericrisco/rsc-harness) into .claude/skills/domains-dns in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill domains-dns -a codex`. Or copy the skill folder (skills/domains-dns in ericrisco/rsc-harness) into .agents/skills/domains-dns in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill domains-dns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/domains-dns, .gemini/skills/domains-dns, .github/skills/domains-dns and .opencode/skills/domains-dns in your project.
Going by SKILL.md and its folder, Domains DNS needs a shell for the scripts in its folder and the command-line tools its instructions call (openssl and curl). Our summary lists: A Bash shell.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Domains DNS is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Domains DNS: Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), OmniRoute Tunnel CLI (diegosouzapw/OmniRoute, 74k stars), OmniRoute Tunnels (diegosouzapw/OmniRoute, 74k stars) and Cdn Setup (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 174 GitHub stars. The repository holds 233 skills in this directory. The repository was last updated on October 7, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.